Apache HTTP Server Heap-Based Buffer Overflow Vulnerability in mod_xml2enc

Vulnerability

A heap-based buffer overflow vulnerability has been identified in Apache HTTP Server versions 2.4.0 prior to 2.4.67, specifically in the mod_xml2enc module. The vulnerability arises in the xml2StartParse function when handling untrusted content, potentially leading to memory corruption.

Impact

Exploitation of this vulnerability causes a heap-based buffer overflow, which can lead to memory corruption and possibly allow for arbitrary code execution.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.68, which addresses this vulnerability.

Added: Jun 8, 2026, 5:16 PM
Updated: Jun 8, 2026, 5:16 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.6
exploitability
7.6
remediation
7.7
relevance
10.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.